feat(auth): add local and OIDC management to tht
This commit is contained in:
@@ -14,6 +14,21 @@ import (
|
||||
|
||||
var ErrUnsafeFile = errors.New("unsafe file")
|
||||
|
||||
// EnsurePrivateDirectory creates only the final canonical directory with the platform's
|
||||
// owner-only protection, or validates an existing directory has that protection.
|
||||
func EnsurePrivateDirectory(path string) error {
|
||||
if err := ValidateCanonicalPath(path); err != nil {
|
||||
return err
|
||||
}
|
||||
if err := requireCanonicalDirectory(filepath.Dir(path)); err != nil {
|
||||
return err
|
||||
}
|
||||
if err := createPrivateDirectory(path); err != nil && !errors.Is(err, os.ErrExist) {
|
||||
return ErrUnsafeFile
|
||||
}
|
||||
return ValidatePrivateDirectory(path)
|
||||
}
|
||||
|
||||
// ValidateCanonicalPath rejects relative or lexically non-canonical paths before they are opened.
|
||||
func ValidateCanonicalPath(path string) error {
|
||||
if !filepath.IsAbs(path) || filepath.Clean(path) != path || strings.Contains(path, string(filepath.Separator)+".."+string(filepath.Separator)) {
|
||||
|
||||
Reference in New Issue
Block a user